Categories
Blog

When Employees Rationalize Misconduct: What CCOs Need to Change

A sales manager needs one more transaction to meet the quarterly target. The customer has not completed the required approvals, but the manager believes the paperwork will arrive tomorrow. Booking the sale today will protect the team’s bonus and keep the regional president satisfied. The manager tells herself that the transaction is real, the delay is administrative, and nobody will be harmed.

This hypothetical illustrates a problem every chief compliance officer should consider. An employee can understand a rule and still construct a convincing reason to disregard it. The compliance challenge includes recognizing the reasoning that makes a violation feel acceptable before the employee acts.

Todd Haugh examined that challenge in The Trouble With Corporate Compliance Programs, published in the Fall 2017 issue of MIT Sloan Management Review. Drawing on behavioral ethics and criminology, Haugh argued that compliance programs need to address how employees make ethical decisions and rationalize misconduct. His analysis laid the foundation for this discussion; the operational recommendations I adapted from his article apply that perspective to the CCO’s work.

Examine the Decision Behind the Violation

Compliance professionals devote substantial attention to policies, training, approvals, and investigations. Each has a role. Yet a completed training course tells us relatively little about how an employee will respond when a supervisor demands a result that appears impossible to achieve within the rules.

Haugh’s central contribution was treating rationalization as something that can precede misconduct and help enable it. (The same is true in the Fraud Triangle.) Drawing on criminological research, including Donald Cressey’s work, Haugh explained how people can make a breach of trust seem consistent with their view of themselves as good people.

For the CCO, this changes the inquiry. Alongside asking whether an employee knew the rule, ask what made bypassing it appear reasonable. Was the employee protecting a colleague? Responding to a threat of dismissal? Following a practice that managers had repeatedly accepted? Those questions can reveal weaknesses in supervision, incentives, escalation, and accountability. They also help explain why repeating the policy may leave the conditions behind a violation intact.

Recognize the Language of Rationalization

Haugh identified eight common rationalizations: denying responsibility, denying injury, denying the victim, condemning the condemners, appealing to higher loyalties, using a ledger metaphor, claiming entitlement, and claiming relative acceptability or normality.

Several relate directly to daily compliance work. An employee who says a supervisor left no choice may be denying responsibility. Someone who minimizes the consequences of an inaccurate record may be denying injury. A manager who defends a questionable payment as necessary to protect the business may be appealing to higher loyalties. An executive who invokes years of excellent performance to excuse a violation may be treating past contributions as credits against present misconduct.

The practical value of these categories lies in the questions they generate. When someone defends a practice as common across the industry, the CCO should explore how the company evaluates that practice and who has approved it. When loyalty to the business becomes the explanation, ask which business interest the conduct actually serves and what risks it creates.

Such statements warrant inquiry. They do not, by themselves, establish misconduct. A useful discussion must leave room for employees to describe pressure, uncertainty, and disagreement candidly.

Put Business Pressure Within the Compliance Review

Haugh discussed Wells Fargo’s sales practices as an example of how organizational pressure can overwhelm formal ethics messaging. In Haugh’s view, aggressive sales expectations helped create an environment in which employees could rationalize improper behavior despite instructions against it. The broader lesson for CCOs is to examine the operating conditions surrounding a control. A policy requiring approval has limited practical support if management consistently rewards employees who bypass the process to deliver faster results.

Consider a third-party onboarding process. The written procedure requires due diligence before engagement. The business promises the intermediary an immediate start date, procurement receives the request late, and the responsible employee is evaluated on speed. Compliance then encounters an urgent request for an exception.

The proposed response should reach beyond that individual exception. Who committed the company before review? Why did the planning process omit the approval period? Does management treat compliance review as part of the transaction schedule? Repeated urgency deserves examination as a management practice. The CCO should bring those findings to the business owner with a concrete correction, an accountable executive, and a timetable.

Practice the Conversation Employees Need to Have

Haugh recommended discussion and storytelling to help employees recognize rationalizations. This approach gives compliance training a useful operational purpose: rehearsing the conversation that must occur when commercial pressure and an ethical obligation collide. Use a scenario drawn from your organization’s actual work, with identifying details removed where necessary. Ask participants to explain the pressure, identify the affected parties, describe the proposed justification, and decide how they would respond. Then require a practical answer. Whom would the employee contact? Can the transaction pause? Who can authorize an alternative? What should the employee say to a manager who insists on proceeding?

Managers should participate because their response determines whether the proposed solution is credible. If the training encourages escalation but the supervisor treats questions as disloyalty, the employee receives conflicting instructions. The CCO can use these sessions to identify unclear responsibilities and impractical procedures. Training becomes a source of information about how work gets done, as well as an opportunity to explain expectations.

Connect Incentives and Accountability

Haugh also emphasized incentives and organizational culture. For compliance practitioners, the application is direct: examine the behaviors that receive recognition, promotion, and protection. A company may praise integrity while celebrating a commercial result without asking how it was achieved. A high performer may receive repeated exceptions unavailable to others. Employees can reasonably interpret those decisions as evidence of management’s priorities.

The CCO should work with human resources and business leadership to incorporate performance metrics into evaluations. Relevant evidence might include how a manager responds to concerns, handles approval requirements, and corrects recurring control failures. Recognition also has a role. With appropriate confidentiality, leadership can acknowledge a team that raised a concern early or found an acceptable way to complete a difficult transaction. The explanation should make it clear that the conduct is worth repeating.

Accountability must extend to supervisors whose instructions or tolerated practices contributed to a problem. Otherwise, remediation may remove an employee while preserving the management behavior that shaped the decision.

Give the Board Evidence About Behavior

Board reporting should help directors understand whether the program influences business decisions. Training completion and policy certifications provide useful coverage information. They need context from the company’s operating experience. A CCO might report recurring reasons for approval exceptions, examples of management responses to escalation, or repeated control failures concentrated within a business unit. Such information can help directors question whether performance expectations and compliance obligations are aligned.

Interpretation matters. More reported concerns could reflect greater trust in the reporting process. Fewer exceptions could reflect better planning or a failure to record deviations. Explain the evidence, its limitations, and the follow-up needed before presenting a conclusion about effectiveness.

Action Steps for the CCO

Haugh’s article challenged compliance leaders to take employee decision-making seriously. Turn that insight into a focused review:

  1. Review a sample of closed matters. Identify the justifications employees offered, the pressures they described, and management’s role. Look for recurring conditions across cases.
  2. Examine one business process. Select a process with frequent exceptions or urgent approvals. Determine where planning, incentives, or unclear authority encourage employees to bypass requirements.
  3. Run a manager-led scenario discussion. Practice recognizing rationalizations and responding to pressure. Record procedural gaps that prevent employees from taking the expected action.
  4. Assign corrective actions to business owners. Address the underlying workflow or management practice, with deadlines and evidence of completion.
  5. Report what changed. Show senior management and the board how the intervention affected decisions, exceptions, or recurring issues. Distinguish observed improvement from conclusions that still require evidence.

The CCO’s task is to make ethical conduct workable under the conditions employees actually face. That requires understanding the justifications for misconduct and changing the business practices that give those justifications force.

Categories
Blog

Roman Philosophers and the Foundations of a Modern Compliance Program: Part 2 Seneca on Pressure and Compliance

I recently wrote a series on the direct link between ancient Greek Philosophers and modern corporate compliance programs and compliance professionals. It was so much fun and so well-received that I decided to follow up with a similar series on notable Roman Philosophers. This week, we will continue our exploration of the philosophical underpinnings of modern corporate compliance programs and compliance professionals by looking at five philosophers from Rome, both from the Roman Republic and the Roman Empire.

Yesterday, we considered Cicero and the duty, law, and the moral limits of business; today, we will look at Seneca and power, pressure, and ethical decision-making under stress; upcoming blog posts include Marcus Aurelius and ethical leadership and tone at the top; Varro and corporate governance; and Lucretius to explore rationality, fear, and risk perception. Today, we continue with Seneca on pressure and when compliance matters the most.

I. Seneca in Context: Ethics from Inside Power

Lucius Annaeus Seneca did not write philosophy from a safe distance. He lived at the center of Roman power, wealth, and danger. As tutor and later advisor to Emperor Nero, Seneca understood how quickly ethical intentions could be compromised by fear, ambition, loyalty, and survival. He also understood how people justify those compromises to themselves.

Seneca’s writings, particularly Letters from a Stoic and On Anger, are not abstract moral treatises. They are practical examinations of how human beings behave when placed under stress. He was deeply concerned with emotional excess, not because emotions were immoral, but because unchecked emotion distorts judgment. Anger, fear, greed, and the desire for approval all lead otherwise rational people to make decisions they later defend as necessary.

For Seneca, ethical failure was rarely sudden. It was incremental. People crossed lines not because they intended to be corrupt, but because they convinced themselves that circumstances demanded flexibility. This insight makes Seneca indispensable to the modern compliance professional, whose greatest challenge is not policy design, but behavior under pressure.

II. The Compliance Problem Seneca Illuminates: Rationalization Under Stress

Most compliance programs are designed around rules, controls, and reporting structures. Far fewer are designed with human psychology in mind. Seneca would argue that this is a critical oversight. Modern compliance failures often occur in high-pressure environments: aggressive sales targets, looming deadlines, competitive markets, political instability, or financial distress. In these moments, individuals do not typically reject ethical norms outright. Instead, they rationalize deviations as temporary, necessary, or harmless.

Common rationalizations include:

  • “This is how business is done here.”
  • “We will fix it later.”
  • “No one is really harmed.”
  • “Leadership expects results.”
  • (and my personal favorite) “We’ve always done it this way.”

Seneca warned that these internal narratives are more dangerous than ignorance. Once people justify unethical conduct to themselves, external controls become less effective. A policy cannot compete with a story someone tells themselves to preserve status, income, or safety. The DOJ, particularly in its various iterations of the Evaluation of Corporate Compliance Programs (ECCP), has increasingly focused on this dynamic. In recent enforcement actions, regulators have emphasized root-cause analysis, asking not only what rule was broken but also why individuals felt compelled to break it. Pressure, incentives, and cultural signals consistently appear as contributing factors.

Seneca teaches that compliance programs must anticipate rationalization. It is not enough to say “do not do this.” Organizations must understand when and why people will convince themselves that doing it is acceptable.

III. Modern Corporate Application: Seneca, DOJ Expectations and Behavioral Compliance

The ECCP explicitly asks whether a company’s risk assessment and controls account for “the types of misconduct most likely to occur” and whether the company has “addressed the root causes of misconduct.” These questions align directly with Seneca’s insights. Consider major enforcement actions involving systemic bribery, fraud, or manipulation of controls. In cases such as the Wells Fargo fraudulent accounts scandal or the Volkswagen emissions testing scandal, both of which involved employees operating under intense performance pressure. While not all wrongdoing can be excused by culture, regulators repeatedly noted environments where employees felt trapped between expectations and ethics.

A Seneca-informed compliance program would focus on several practical measures.

First, risk assessments should explicitly identify pressure points. Compliance should map where incentives, deadlines, or market conditions increase the likelihood of rationalization. This includes sales functions, third-party relationships, emerging markets, and crises.

Second, training should move beyond rules into scenario-based discussions. Seneca believed self-awareness was an ethical discipline. Modern compliance training should confront common rationalizations directly, helping employees recognize them before they take hold. DOJ guidance increasingly favors practical, tailored training over generic training.

Third, escalation pathways must be realistic under stress. A hotline that exists only on paper will not be used when fear of retaliation or failure dominates. Seneca understood that fear silences conscience. Effective compliance programs must demonstrate that speaking up under pressure is protected, valued, and acted upon.

Fourth, leadership messaging matters most during crises. Seneca warned that leaders set moral boundaries through behavior, not speeches. The DOJ has emphasized that how management responds to misconduct is a key indicator of program effectiveness. When leaders excuse results achieved through questionable means, rationalization spreads quickly.

Finally, compliance must be present before the crisis, not introduced afterward. Seneca would view reactive compliance as inherently weak. Ethical resilience must be built in advance, when judgment is clear, and stakes are lower.

Key Takeaways for Compliance Professionals

1. Behavioral Risk. Compliance professionals should view Seneca as a guide to behavioral risk, not philosophical pessimism. Seneca focuses on how real people behave under pressure rather than on abstract ethical ideals. He recognizes that stress, fear, ambition, and loyalty distort judgment long before formal rules are broken. For compliance professionals, Seneca provides a framework for understanding why misconduct occurs even in organizations with well-designed programs.

2. Pressure Points. Compliance should identify and manage pressure points where rationalization thrives. High-performance targets, crises, and competitive markets create environments where ethical shortcuts are easily justified. Seneca teaches that rationalization flourishes when people feel trapped between expectations and consequences. Compliance programs must proactively map and mitigate these pressure points rather than react after misconduct occurs.

3. Training Design. Compliance should design training that addresses how people actually make decisions under stress. Traditional rule-based training assumes calm, rational decision-making, which rarely occurs in real-world situations. Seneca reminds us that ethical failure often occurs in moments of emotional intensity rather than in deliberation. Effective compliance training should use scenarios and realistic dilemmas that reflect pressure, ambiguity, and competing incentives.

Compliance should ensure escalation mechanisms work when fear and incentives collide. A hotline or reporting channel is ineffective if employees do not trust it during high-risk moments. Seneca understood that fear silences conscience and discourages disclosure. Compliance programs must test whether escalation pathways function when the personal cost of speaking up feels high.

4. Leadership Engagement. Compliance should engage leadership on how their responses to pressure shape ethical behavior. Leaders signal ethical boundaries most clearly when responding to setbacks, failures, or missed targets. Seneca warned that inconsistent or emotionally driven leadership responses accelerate ethical decay. Compliance professionals must ensure leaders understand that their reactions under pressure become cultural instruction.

  • Compliance should focus on prevention through awareness, not punishment after failure. Seneca emphasized self-awareness as the first defense against moral error. Compliance messaging that only appears after misconduct reinforces fear rather than learning. Ongoing communication about pressure, rationalization, and ethical expectations strengthens resilience before problems arise.
  • Finally, Seneca instructs us that ethical systems fail not because people abandon values, but because they convince themselves that those values can wait. A compliance program that ignores pressure is a program designed to fail when it matters most. Rationalization is the quiet mechanism through which ethical erosion occurs. Seneca shows that delay, exception-making, and “temporary” compromises accumulate into systemic failure. Compliance programs that do not confront rationalization directly leave themselves exposed at their most vulnerable moments.

Conclusion

Seneca exposes the internal dynamics that cause compliance programs to fail under pressure. He shows us how fear, ambition, and rationalization erode ethical judgment, even when rules are clear and controls are in place. But Seneca largely examines the problem from the inside out, focusing on how individuals respond to external forces. That analysis leads directly to the next question in the compliance lifecycle: what responsibility does the individual retain when pressure is real, and authority is unequal? This is where Seneca gives way to Epictetus.

Join us tomorrow as we explore Varro and corporate governance for your compliance regime.